{"api_version":"1","generated_at":"2026-09-25T23:18:14+00:00","cve":"CVE-2026-18515","urls":{"html":"https://cve.report/CVE-2026-18515","api":"https://cve.report/api/cve/CVE-2026-18515.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18515","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18515"},"summary":{"title":"IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.","description":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-14 19:17:16","updated_at":"2026-09-16 19:22:22"},"problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286974","name":"https://www.ibm.com/support/pages/node/7286974","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18515","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18515","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"i","version":"affected 7.6","platforms":[]},{"source":"CNA","vendor":"IBM","product":"i","version":"affected 7.5","platforms":[]},{"source":"CNA","vendor":"IBM","product":"i","version":"affected 7.4","platforms":[]},{"source":"CNA","vendor":"IBM","product":"i","version":"affected 7.3","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\n\n\nIBM i Release5770-SS1 Option 3\nPTF Number(s)PTF Download Link(s)7.6SJ11196\nSJ11337 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337 \n\n7.5SJ11197\nSJ11336 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336 \n\n7.4SJ11200\nSJ11335 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335 \n\n7.3SJ11187\nSJ11394 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394 \n\n\n\nIBM i Release5770-SS1 Option 34\nPTF Number(s)PTF Download Link(s)7.6SJ11377 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377 7.5SJ11376 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376 7.4SJ11375 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375 7.3SJ11374 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374 \n\n\n\n\n\n\n\nIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"18515","cve":"CVE-2026-18515","epss":"0.002770000","percentile":"0.202340000","score_date":"2026-09-16","updated_at":"2026-09-17 00:07:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-18515","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-14T19:10:24.138205Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-14T19:22:58.738Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"product":"i","vendor":"IBM","versions":[{"status":"affected","version":"7.6"},{"status":"affected","version":"7.5"},{"status":"affected","version":"7.4"},{"status":"affected","version":"7.3"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.</p>"}],"value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-14T18:26:59.756Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7286974"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>IBM strongly recommends addressing the vulnerability now.</strong></p><p></p><div><table><colgroup><col/><col/><col/></colgroup><thead><tr><td><strong>IBM i Release</strong></td><td><strong>5770-SS1 Option 3<br/></strong><strong>PTF Number(s)</strong></td><td><strong>PTF Download Link(s)</strong></td></tr></thead><tbody><tr><td>7.6</td><td>SJ11196<br/>SJ11337</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337</a></div></td></tr><tr><td>7.5</td><td>SJ11197<br/>SJ11336</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336</a></div></td></tr><tr><td>7.4</td><td>SJ11200<br/>SJ11335</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335</a></div></td></tr><tr><td>7.3</td><td>SJ11187<br/>SJ11394</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394</a></div></td></tr></tbody></table></div><div><table><colgroup><col/><col/><col/></colgroup><thead><tr><td><strong>IBM i Release</strong></td><td><strong>5770-SS1 Option 34<br/></strong><strong>PTF Number(s)</strong></td><td><strong>PTF Download Link(s)</strong></td></tr></thead><tbody><tr><td>7.6</td><td>SJ11377</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377</a></td></tr><tr><td>7.5</td><td>SJ11376</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376</a></td></tr><tr><td>7.4</td><td>SJ11375</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375</a></td></tr><tr><td>7.3</td><td>SJ11374</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374</a></td></tr></tbody></table></div><p></p><p>IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.</p>"}],"value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\n\n\nIBM i Release5770-SS1 Option 3\nPTF Number(s)PTF Download Link(s)7.6SJ11196\nSJ11337 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337 \n\n7.5SJ11197\nSJ11336 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336 \n\n7.4SJ11200\nSJ11335 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335 \n\n7.3SJ11187\nSJ11394 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394 \n\n\n\nIBM i Release5770-SS1 Option 34\nPTF Number(s)PTF Download Link(s)7.6SJ11377 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377 7.5SJ11376 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376 7.4SJ11375 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375 7.3SJ11374 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374 \n\n\n\n\n\n\n\nIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products."}],"title":"IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i."}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-18515","datePublished":"2026-09-14T18:26:59.756Z","dateReserved":"2026-07-31T17:56:14.883Z","dateUpdated":"2026-09-14T19:22:58.738Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-14 19:17:16","lastModifiedDate":"2026-09-16 19:22:22","problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-14T19:10:24.138205Z","id":"CVE-2026-18515","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18515","Ordinal":"1","Title":"IBM i is Affected By Multiple Vulnerabilities in Navigator for i","CVE":"CVE-2026-18515","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18515","Ordinal":"1","NoteData":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.","Type":"Description","Title":"IBM i is Affected By Multiple Vulnerabilities in Navigator for i"}]}}}